This patch series adds LUKS full disk encryption support using firmware TPM
(fTPM) for TI K3 platforms. The implementation provides hardware-backed
encryption with keys sealed by TPM running in OP-TEE and stored in eMMC RPMB.
Background:
TI K3 platforms do not have integrated discrete TPM hardware. To provide
TPM 2.0 functionality, this implementation uses firmware TPM (fTPM) - a
Trusted Application running in OP-TEE secure world. The fTPM provides
standard TPM 2.0 interfaces while leveraging ARM TrustZone for isolation
and eMMC RPMB (Replay Protected Memory Block) for secure persistent storage.
Key features:
- Conditional builds: Enabled via DISTRO_FEATURES += "luks" with
MACHINE_FEATURES as 'optee-ftpm'
- No impact on default SDK builds
- In-place encryption on first boot
- TPM persistent handle for key storage (0x81080001)
- Secure key storage in eMMC RPMB via OP-TEE
- Security model similar to CIP Core
Use case:
This is designed for K3 platforms requiring secure boot and encrypted
storage, such as industrial automation, automotive, and IoT gateways where
discrete TPM chips are cost-prohibitive but security requirements demand
hardware-backed encryption.
Testing:
- Tested on AM62x platform with kernel 6.18
- First boot: Successful in-place LUKS encryption
- Subsequent boots: Successful TPM unsealing and boot
The series is structured as follows:
1. Kernel configuration for LUKS and crypto support
2. LUKS encryption initramfs module with fTPM key management
3. Dynamic layer registration and initramfs configuration
---
Changes in v8:
- Update 'meta-security' to 'tpm-layer' collection name in LAYERRECOMMENDS
- Only register 'tpm-layer' in BBFILES_DYNAMIC (removed 'security' collection)
- Rename dynamic-layers/security/ to dynamic-layers/tpm-layer/ to match
collection
- Add S = "${UNPACKDIR}" to initramfs-module-luks-ftpm recipe to fix build
warning
- Link to v7:
https://lore.kernel.org/all/[email protected]/
Changes in v7:
- Added 'tpm-layer' collection registration to BBFILES_DYNAMIC for TPM packages
- Added meta-security to LAYERRECOMMENDS
- Link to v6:
https://lore.kernel.org/all/[email protected]/
Changes in v6:
- Moved initramfs-module-luks-ftpm to dynamic-layers/security/
- Added BBFILES_DYNAMIC registration for 'security' layer in layer.conf
- Eliminates hard dependency on meta-security layer
- Packagegroup LUKS logic moved from base .bb to dynamic-layers bbappend
- Link to v5:
https://lore.kernel.org/all/[email protected]/
Changes in v5:
- change from MACHINE_FEATURES 'luks-encryption' to DISTRO_FEATURES 'luks'
- implement dual gating using existing MACHINE_FEATURES 'optee-ftpm'
- optimize kernel config - remove unnecessary CBC, ECB, ESSIV, LRW, PCBC,
SHA256_ARM64
- packagegroup-ti-core-initramfs.bb changes moved to patch 3 from patch2
- Link to v4:
https://lore.kernel.org/all/[email protected]/
Changes in v4:
- remove encrypted-boot-common.inc and use existing ti-core-initramfs.inc
- Link to v3:
https://lore.kernel.org/all/[email protected]/
Changes in v3:
- remove separate sdimage.wks for encrypted boot, default works
- update encrypted-boot-common.inc to use existing hook for adding
TI_CORE_INITRAMFS_ENABLED dependency on luks-encryption flag
- add logic to verify if partition has enough space for LUKS header before
starting encryption
Changes in v2:
- changes to use existing ti-core-initramfs instead of adding separate
- cleanup in previous init script as per comments in v1
- /usr/bin/busybox logs updated to echo, mesg, info
- WORKDIR changed to UNPACKDIR
- Link to v1:
https://lore.kernel.org/all/[email protected]/
Shiva Tripathi (3):
linux-ti-staging: Add LUKS encryption config
initramfs-module-luks-ftpm: Add fTPM support
conf: Enable dynamic tpm-layer support for LUKS
meta-ti-bsp/conf/layer.conf | 3 +
.../machine/include/ti-core-initramfs.inc | 2 +-
.../initramfs-module-luks-ftpm/luksftpm | 341 ++++++++++++++++++
.../initramfs-module-luks-ftpm_1.0.bb | 43 +++
.../packagegroup-ti-core-initramfs.bbappend | 3 +
.../linux/linux-ti-staging-6.18/luks-ftpm.cfg | 22 ++
.../linux/linux-ti-staging_6.18.bb | 8 +
7 files changed, 421 insertions(+), 1 deletion(-)
create mode 100644
meta-ti-bsp/dynamic-layers/tpm-layer/recipes-ti/initramfs/initramfs-module-luks-ftpm/luksftpm
create mode 100644
meta-ti-bsp/dynamic-layers/tpm-layer/recipes-ti/initramfs/initramfs-module-luks-ftpm_1.0.bb
create mode 100644
meta-ti-bsp/dynamic-layers/tpm-layer/recipes-ti/initramfs/packagegroup-ti-core-initramfs.bbappend
create mode 100644
meta-ti-bsp/recipes-kernel/linux/linux-ti-staging-6.18/luks-ftpm.cfg
--
2.34.1
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#19782):
https://lists.yoctoproject.org/g/meta-ti/message/19782
Mute This Topic: https://lists.yoctoproject.org/mt/118403784/21656
Group Owner: [email protected]
Unsubscribe: https://lists.yoctoproject.org/g/meta-ti/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-